Banner 9.x and SAML / Shibb

Jorj Bauer jorj at temple.edu
Mon Aug 15 18:32:16 EDT 2016


We've set up a proof of concept using Shib, and hope to complete that work early this fall. We only worked through the most basic authentication before having to divert energies to other upgrades.

The only gotcha so far has been that the Banner products (running through WebLogic) were determined to perform SSL v2 HELLOs, which our Shib server rejects. It took a little while to diagnose that and then fix up WebLogic's crypto. 

Internally, Ellucian staff appear to be on a dozen different pages regarding SAML and Shib support and configuration. I hope that is beginning to improve...

-- Jorj

Sent from my iPhone

> On Aug 15, 2016, at 18:18, IAM David Bantz <dabantz at alaska.edu> wrote:
> 
> Our ERP manager called attention to Ellucian's documentation indicating Banner 9.x can support SAML authentication rather than CAS. There' seems to be quite a caveat for Shibboleth IdP users though:
> 
>> You can... change the configuration of Banner Admin Pages after deployment to use the SAML protocol for user authentication with EIS as the authentication server.
>> Note: If you are using an authentication server other than EIS, you must adapt these instructions accordingly. 
> 
> We currently protect Banner and Banner-integrated apps with CAS.
> 
> Are there institutions or individuals on this list who:
> 
> (a) have made a written value / benefit calculation of switching Banner login from CAS to SAML in 9.x using Shibboleth IdP ? and/or
> 
> (b) worked through what "adaptations" of the instructions are necessary for use of Shibboleth IdP (rather than EIS) ?
> 
> and are willing to share them?
> 
> David Bantz
> -- 
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160815/e77f441f/attachment-0001.html>


More information about the users mailing list